Malicious RTF — malware analysis report

Static analysis result for SHA-256 1cd785c84bf55587…

MALICIOUS

RTF

1001.5 KB Created: 2018-03-22 First seen: 2018-03-30
MD5: 63aa62ffd0b9aaaaa543fed0de19943d SHA-1: 6821fbea3f4ab689a1a9efe5a6bf6fc9e6a5b782 SHA-256: 1cd785c84bf55587366945e1d1ceda4cbd748f08212fe2a6fba567fde044050c
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c42.bin rtf-objdata-decoded RTF \objdata at offset 0x2C42 28731 bytes
SHA-256: 714be4bdc218b544b63a14e53fecc03d5dc5e3a530f06afca41e9416bad35f25
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00016c83.bin rtf-objdata-decoded RTF \objdata at offset 0x16C83 28731 bytes
SHA-256: 9f11019af3ac07d7904db0fcdc1c7d142fddb327fc6bd498b05df4e02bcec438
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002acc4.bin rtf-objdata-decoded RTF \objdata at offset 0x2ACC4 28731 bytes
SHA-256: 137243f1c8a925e9e13e39ae65cf4ac10a6fda44bac9b6b29d61854c609a5c9b
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003ed05.bin rtf-objdata-decoded RTF \objdata at offset 0x3ED05 28731 bytes
SHA-256: 9197d3aadf5f53db22bb221ef242f838288612b07f9f0f2e9e500c8549a8d8a9
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00052d46.bin rtf-objdata-decoded RTF \objdata at offset 0x52D46 28731 bytes
SHA-256: 73079bf225c1b7299977a96ca0bc43eefd7171b5ce7d38ee98763e279c217cbd
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00066d87.bin rtf-objdata-decoded RTF \objdata at offset 0x66D87 28731 bytes
SHA-256: 2e7765c0ead6f52087060e2ef8f9a99b22bdbdb89609e96959b8ba5fbf89ea45
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007ae12.bin rtf-objdata-decoded RTF \objdata at offset 0x7AE12 28731 bytes
SHA-256: c6be687cb1301d312b4ceece9aeecf649a677b3c7bb14d42b3264aefd68b6667
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008ee53.bin rtf-objdata-decoded RTF \objdata at offset 0x8EE53 28731 bytes
SHA-256: fa573fbc0626d7f000cf432d9eaf3f969b43a07db6d83068d0321333faf101dc
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2e94.bin rtf-objdata-decoded RTF \objdata at offset 0xA2E94 28731 bytes
SHA-256: 59ca74832c9194739c8971099759d4b6222930db0881c058359ae722970a02fe
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6ed5.bin rtf-objdata-decoded RTF \objdata at offset 0xB6ED5 28731 bytes
SHA-256: 0844182bac0ebd249851df227be8ac52d01dcfaaf9330836b3869c68a8cfd8b3
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_10_off000caf16.bin rtf-objdata-decoded RTF \objdata at offset 0xCAF16 28731 bytes
SHA-256: 896d7afb2264b7ee2f720f5f7a069ebf5d896c77f7241fd0e3c586a9eb7e099b
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_11_off000def57.bin rtf-objdata-decoded RTF \objdata at offset 0xDEF57 28731 bytes
SHA-256: d486450ff5153f425860530845ea2c25f0735f2baf4ca0f77fc792a24b189f04
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely